Healthcare3 mins read

CareCloud Notifies Hundreds of Thousands After Hackers Stole Medical Records

CareCloud is notifying patients after hackers accessed a protected health data store and stole medical records, with at least 345,000 people affected so far.

What Happened at CareCloud

CareCloud has begun sending letters to hundreds of thousands of people after hackers stole medical records in a cyberattack earlier this year. The company said hackers struck one of its protected health data stores, according to the TechCrunch report. CareCloud had previously said little about the breach after first disclosing in March that hackers accessed one of its six stores of patient data.

How Many People Are Affected So Far

TechCrunch reported that the breach affects at least 345,000 people across the United States, based on listings with several attorneys general and a disclosure filed with Maine’s attorney general. New disclosures seen by TechCrunch put the affected population at nearly 350,000 so far. The number may rise as more state filings are submitted.

Timeline and Access Details

A data breach notice filed with California’s attorney general said hackers had access to one of CareCloud’s electronic health record data stores for at least six days, between March 10 and March 16. CareCloud said a hacker claimed to have exfiltrated data from databases. TechCrunch reported it was unaware of any ransomware or extortion group publicly taking credit for the breach.

What Data Was Stolen

The notices said the stolen data included names, postal addresses, Social Security numbers, and government-issued identification numbers such as passports and driver’s licenses. They also said financial information, including bank account information and payment card numbers, was affected. The breach also involved medical and health-related information, making the incident especially sensitive for affected patients.

Why This Breach Matters

CareCloud stores patient records for more than 45,000 providers across the U.S., including doctors’ offices, hospitals, and other medical practices. The incident adds to a series of healthcare-related breaches reported this year, including breaches involving TriZetto, NYC Health + Hospitals, and Craneware. For patients receiving notices, the key takeaway is that the exposed information may span identity, financial, and health data.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile